An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components
Metrics
Affected Vendors & Products
References
History
Fri, 11 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | AppFlowy Remote Code Execution via URI Launch Functions |
Fri, 11 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | AppFlowy Remote Code Execution via URI Launch Functions |
Thu, 10 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary code execution via improper URI handling in AppFlowy |
Thu, 10 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote code execution via improper URI and local file handling in AppFlowy | Arbitrary code execution via improper URI handling in AppFlowy |
| Weaknesses | CWE-78 |
Thu, 10 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote code execution via improper URI and local file handling in AppFlowy | |
| Weaknesses | CWE-78 |
Thu, 10 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Thu, 10 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-09-10T00:00:00.000Z
Updated: 2026-09-10T17:47:57.526Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-52097
Updated: 2026-09-10T17:46:51.546Z
Status : Deferred
Published: 2026-09-10T17:17:04.820
Modified: 2026-09-10T19:58:20.507
Link: CVE-2026-52097
No data.